LiveActive security incident?Get immediate response
CVE Record

CVE-2021-33818: An issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67.

An issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2021-33818 describes a denial-of-service issue in the UniFi Protect G3 FLEX Camera firmware UVC.v4.30.0.67. A remote party may be able to tie up the camera web server with incomplete HTTP requests until resources are exhausted, interrupting access to the device.

Executive priority

Treat this as an availability risk to camera operations, not a confirmed data compromise issue. Prioritize exposed or business-critical cameras, especially those reachable outside trusted networks, while waiting for clear vendor remediation details.

Technical view

The CVE describes slow HTTP request resource exhaustion against the camera web server. The record names UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67 and references slowhttptest and a public proof-of-concept page. No CVSS score, CWE, vendor advisory, or fixed version is provided in the supplied sources.

Likely exposure

Exposure is most relevant where the camera web interface is reachable by untrusted networks. The supplied data does not confirm whether authentication is required, which services are exposed by default, or whether other UniFi camera models or firmware versions are affected.

Exploitation context

The CVE is not listed as CISA KEV in the provided bundle. The sources include a public proof-of-concept reference and a common slow HTTP testing tool, but they do not establish active exploitation in the wild.

Researcher notes

The record is sparse: no CVSS, CWE, affected CPE, authentication detail, or vendor fix is included. Analysis should stay limited to the named model and firmware unless independent vendor evidence expands scope.

Mitigation direction

  • Check Ubiquiti or UniFi firmware guidance for a fixed release before changing production devices.
  • Restrict camera web access to trusted management networks or VPN paths only.
  • Block direct internet exposure for camera HTTP services.
  • Monitor device availability and restart affected services only as an operational recovery measure.
  • Use network controls to limit slow or incomplete HTTP connections where supported.

Validation and detection

  • Inventory UniFi Protect G3 FLEX cameras and record firmware versions.
  • Prioritize any device running UVC.v4.30.0.67 for review.
  • Confirm whether camera web interfaces are reachable from untrusted networks.
  • Review logs or monitoring for repeated incomplete HTTP connections and availability drops.
  • Document whether vendor guidance identifies a fixed firmware version.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-33818 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.